BrbBot
- First seen
- 2018-04-10 00:00:00
- Malware type
- botnet, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-05-05 09:57:17
- Profile updated
- 2026-07-07 14:50:29
Targeted industries: financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:ca
Context
BrbBot is a botnet malware family primarily targeting financial services and technology sectors. It is known for its credential-stealing capabilities, often distributed via phishing campaigns.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Brbbot (yara-rule)
- MALPEDIA_Win_Brbbot_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Brbbot (report)
- github.com — Brbbot.Md (report)